Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Generic Trojan & Tracking cookie removal


  • This topic is locked This topic is locked
12 replies to this topic

#1 Salamander Huner

Salamander Huner

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:55 AM

Posted 11 August 2010 - 05:18 PM

Hi,

My machine began to act corrupt a few months ago with files not working properly and slow run time...
it came to head one day with a battalion of pop-ups and this antivir solution pro and malware doctor installed and running from my desktop...I knew I was in for it..eventually freeing up enough RAM to download and run MalwareBytes cleaned up a major pile of crap and also printed a text file which allowed to view some of the infections.

I thought I was done...I noticed my machine was still running funny and my body happened to stop by and quickly glanced at the malwarebytes printout and began to search the web for removal tools to pull the bugs out from the roots...this was all new to me but I discovered that you guys (bleeping computer) were a trusted server of PC healing.

We followed the instructions for the removal of some Hiloti Trojan using ComboFix...This seemed to work and I observed the tool pull this bug from my external drive in a autorestore/autorun file (how wicked I thought).

Anyway, finally running the a full scan which came up clean, I thought we were actually done. Now I am using my nice "clean" computer with AVG (free) and I get a warning about some tracking cookie:

("Found Tracking cookie.2o7";"c:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite";"";"8/11/2010, 1:56:55 PM";"file";"C:\Program Files\Mozilla Firefox\firefox.exe")

every time I search the web...It urks me because the software doesn't seem to do anything about this...I took a look into the Virus Vault and found that it had discovered two other Trojan threats:

"Trojan horse Generic18.AIKE";"c:\System Volume Information\_restore{6DD1964A-18CA-4395-8E80-F4D6C19D7DA1}\RP919\A0147075.sys";"Moved to Virus Vault";"7/20/2010, 11:29:56 AM";"file";"C:\WINDOWS\system32\MRT.exe"
"Trojan horse Downloader.Generic10.BEH";"c:\System Volume Information\_restore{6DD1964A-18CA-4395-8E80-F4D6C19D7DA1}\RP916\A0144505.dll";"Moved to Virus Vault";"7/20/2010, 11:28:34 AM";"file";"C:\WINDOWS\system32\MRT.exe"

Which it moved into the vault but what good does that even do; I did not see any file deleted or anything else reassuring so it seems AVG is not cutting it here, anyway, I went on the web to search out a trojan removal utility and followed the instructions I found on a post that sounded almost exactly similar to what I was seeing most recently. It had me use the OTL utility with some custom instructions...I ralize now that it is best to simply post my own problems and thereby get more specific help for my needs...sorry if I jumped the gun by running this utility I preened from some other post. Anyway the custom instructions I ran are as follows in case it differs and I did something wrong:

%SYSTEMDRIVE%\*.exe
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys
symmpi.sys
adp3132.sys
mv61xx.sys
nvraid.sys
/md5stop
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
%systemroot%\system32\drivers\*.sys /90

If thats all good, or whatever, then here are the text files that followed:

I have attached the two text files: OTL and Extras to this message since they are massive...

Thank you Thank you so much for your expertise and guidance in these issues and I look forward to hearing back for you.





Attached Files



BC AdBot (Login to Remove)

 


#2 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:04:55 AM

Posted 19 August 2010 - 06:24 AM

Welcome to the BleepingComputer Forums.

Since it has been a few days since you scanned your computer with HijackThis, we will need a new HijackThis log. If you have not already downloaded Random's System Information Tool (RSIT), please download Random's System Information Tool (RSIT) by random/random which includes a HijackThis log and save it to your desktop. If you have RSIT already on your computer, please run it again.
  1. Double click on RSIT.exe to run RSIT.
  2. Click Continue at the disclaimer screen.
  3. Please post the contents of log.txt.
Thank you for your patience.

Please see Preparation Guide for use before posting about your potential Malware problem.

If you have already posted this log at another forum or if you decide to seek help at another forum, please let us know. There is a shortage of helpers and taking the time of two volunteer helpers means that someone else may not be helped.

Please post your HijackThis log as a reply to this thread and not as an attachment. I am always leery of opening attachments so I always request that HijackThis logs are to be posted as a reply to the thread. I do not think that you are attaching anything scary but others may do so.

While we are working on your HijackThis log, please:
  1. Reply to this thread; do not start another!
  2. Do not make any changes on your computer during the cleaning process or download/add programs on your computer unless instructed to do so.
  3. Do not run any other tool until instructed to do so!
  4. Let me know if any of the links do not work or if any of the tools do not work.
  5. Tell me about problems or symptoms that occur during the fix.
  6. Do not run any other programs or open any other windows while doing a fix.
  7. Ask any questions that you have regarding the fix(es), the infection(s), the performance of your computer, etc.
Thanks.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#3 Salamander Huner

Salamander Huner
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:55 AM

Posted 20 August 2010 - 02:01 PM

Hi, Thank you for your response. Here are the reports following the requested scans (RSIT, DDS, gmer) :

Logfile of random's system information tool 1.08 (written by random/random)
Run by jada at 2010-08-20 09:59:09
Microsoft Windows XP Professional Service Pack 3
System drive C: has 1 GB (6%) free of 21 GB
Total RAM: 767 MB (17% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:59:37 AM, on 8/20/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17080)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\vVX1000.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\AVG\AVG9\avgfws9.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
D:\Jada\Downloads\RSIT.exe
C:\Program Files\trend micro\jada.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase5483.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (file missing)
O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: Google Update Service (gupdate1c9d023e4b4b290) (gupdate1c9d023e4b4b290) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 10524 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Google Software Updater.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\Microsoft_Hardware_Launch_IPoint_exe.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
&Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll [2010-03-23 940856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2010-07-20 1619296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-05-14 191792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll [2007-09-25 501136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll [2009-08-08 669168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
SingleInstance Class - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll [2010-03-23 160056]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{A057A204-BACC-4D26-9990-79A187E2698E} - AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL []
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll [2010-03-23 940856]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2005-12-10 7311360]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2008-09-06 413696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-10-01 289576]
"mxomssmenu"=C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe [2008-07-21 169312]
"nwiz"=nwiz.exe /install []
"Zune Launcher"=C:\Program Files\Zune\ZuneLauncher.exe [2008-12-12 157312]
"itype"=C:\Program Files\Microsoft IntelliType Pro\itype.exe [2008-06-10 1442888]
"IntelliPoint"=C:\Program Files\Microsoft IntelliPoint\ipoint.exe [2008-06-10 1406024]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"LifeCam"=C:\Program Files\Microsoft LifeCam\LifeExp.exe [2007-05-17 279912]
"VX1000"=C:\WINDOWS\vVX1000.exe [2007-04-10 709992]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2010-07-19 2065760]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-05-08 39408]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
C:\WINDOWS\ehome\ehtray.exe [2005-08-05 64512]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-02-19 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mxomssmenu]
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe [2008-07-21 169312]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\WINDOWS\system32\NvCpl.dll [2005-12-10 7311360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\system32\NvMcTray.dll [2005-12-10 86016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe [2008-01-23 26112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe [2007-09-25 132496]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE [1999-11-04 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2006-02-19 288472]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqthb08.exe [2006-02-10 73728]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
C:\PROGRA~1\INTERV~1\Common\Bin\WINCIN~1.EXE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^jada^Start Menu^Programs^Startup^Microsoft Office Groove.lnk]
C:\PROGRA~1\MICROS~2\Office12\GROOVE.EXE [2009-02-14 337264]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^jada^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
C:\PROGRA~1\MICROS~2\Office12\ONENOTEM.EXE [2009-02-26 97680]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3
"Pml Driver HPZ12"=2
"ose"=3
"odserv"=3
"NBService"=3
"Microsoft Office Groove Audit Service"=3
"HP Status Server"=3
"HP Port Resolver"=3

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2010-07-19 12536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-13 239616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\AIM\aim.exe"="C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\AVG\AVG9\avgam.exe"="C:\Program Files\AVG\AVG9\avgam.exe:*:Enabled:avgam.exe"
"C:\Program Files\AVG\AVG9\avgdiagex.exe"="C:\Program Files\AVG\AVG9\avgdiagex.exe:*:Enabled:avgdiagex.exe"
"C:\Program Files\AVG\AVG9\avgemc.exe"="C:\Program Files\AVG\AVG9\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\AVG\AVG9\avgupd.exe"="C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG9\avgnsx.exe"="C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

======List of files/folders created in the last 1 months======

2010-08-20 09:59:10 ----D---- C:\Program Files\trend micro
2010-08-20 09:59:09 ----DC---- C:\rsit
2010-08-12 22:17:27 ----SHDC---- C:\RECYCLER
2010-08-11 12:25:26 ----HDC---- C:\WINDOWS\$NtUninstallKB982214$
2010-08-11 12:24:59 ----HDC---- C:\WINDOWS\$NtUninstallKB981852$
2010-08-11 12:24:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2079403$
2010-08-11 12:13:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2160329$
2010-08-11 12:12:44 ----HDC---- C:\WINDOWS\$NtUninstallKB980436$
2010-08-11 12:04:11 ----HDC---- C:\WINDOWS\$NtUninstallKB981997$
2010-08-11 12:02:57 ----HDC---- C:\WINDOWS\$NtUninstallKB982665$
2010-08-03 12:00:59 ----HDC---- C:\WINDOWS\$NtUninstallKB2286198$
2010-07-26 20:57:26 ----AC---- C:\ComboFix.txt
2010-07-26 20:13:42 ----ASH---- C:\hiberfil.sys
2010-07-26 19:56:45 ----AC---- C:\Boot.bak
2010-07-26 19:56:38 ----RASHDC---- C:\cmdcons
2010-07-26 19:53:42 ----A---- C:\WINDOWS\zip.exe
2010-07-26 19:53:42 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-07-26 19:53:42 ----A---- C:\WINDOWS\SWSC.exe
2010-07-26 19:53:42 ----A---- C:\WINDOWS\SWREG.exe
2010-07-26 19:53:42 ----A---- C:\WINDOWS\sed.exe
2010-07-26 19:53:42 ----A---- C:\WINDOWS\PEV.exe
2010-07-26 19:53:42 ----A---- C:\WINDOWS\NIRCMD.exe
2010-07-26 19:53:42 ----A---- C:\WINDOWS\MBR.exe
2010-07-26 19:53:42 ----A---- C:\WINDOWS\grep.exe
2010-07-26 19:53:21 ----D---- C:\WINDOWS\ERDNT
2010-07-26 19:49:06 ----ADC---- C:\Qoobox
2010-07-26 19:35:11 ----A---- C:\WINDOWS\ntbtlog.txt
2010-07-22 14:02:25 ----D---- C:\Documents and Settings\jada\Application Data\AVG9

======List of files/folders modified in the last 1 months======

2010-08-20 09:59:10 ----D---- C:\Program Files
2010-08-20 09:58:47 ----D---- C:\WINDOWS\Prefetch
2010-08-20 09:51:11 ----D---- C:\Program Files\Mozilla Firefox
2010-08-20 09:51:01 ----D---- C:\WINDOWS\Temp
2010-08-20 09:50:58 ----D---- C:\WINDOWS\Registration
2010-08-20 09:50:35 ----SD---- C:\WINDOWS\Tasks
2010-08-20 09:50:30 ----D---- C:\WINDOWS
2010-08-20 09:50:05 ----D---- C:\WINDOWS\system32
2010-08-19 21:55:21 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-08-19 21:55:14 ----A---- C:\WINDOWS\ModemLog_Lucent Win Modem.txt
2010-08-19 19:59:55 ----DC---- C:\Documents and Settings\All Users\Application Data\Google Updater
2010-08-18 16:13:46 ----D---- C:\WINDOWS\system32\drivers\Avg
2010-08-18 09:52:46 ----D---- C:\WINDOWS\system32\CatRoot2
2010-08-17 21:59:07 ----D---- C:\Documents and Settings\jada\Application Data\uTorrent
2010-08-11 13:35:15 ----D---- C:\WINDOWS\Microsoft.NET
2010-08-11 13:34:40 ----RSD---- C:\WINDOWS\assembly
2010-08-11 12:59:59 ----DC---- C:\Config.Msi
2010-08-11 12:28:02 ----HD---- C:\WINDOWS\inf
2010-08-11 12:27:22 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-08-11 12:26:59 ----D---- C:\WINDOWS\system32\en-US
2010-08-11 12:26:56 ----D---- C:\Program Files\Internet Explorer
2010-08-11 12:26:33 ----D---- C:\WINDOWS\ie7updates
2010-08-11 12:25:38 ----D---- C:\WINDOWS\system32\drivers
2010-08-11 12:25:37 ----A---- C:\WINDOWS\imsins.BAK
2010-08-11 12:25:21 ----HD---- C:\WINDOWS\$hf_mig$
2010-08-11 12:24:10 ----SHD---- C:\WINDOWS\Installer
2010-08-11 12:24:02 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2010-08-11 12:19:55 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-08-11 12:18:58 ----D---- C:\WINDOWS\WinSxS
2010-08-11 12:04:14 ----D---- C:\Program Files\Movie Maker
2010-08-11 10:45:55 ----D---- C:\WINDOWS\system32\CatRoot
2010-08-03 11:09:31 ----A---- C:\WINDOWS\system32\MRT.exe
2010-07-26 23:30:35 ----A---- C:\WINDOWS\system32\shell32.dll
2010-07-26 20:51:07 ----AC---- C:\WINDOWS\system.ini
2010-07-26 20:50:41 ----D---- C:\WINDOWS\system32\drivers\etc
2010-07-26 20:47:40 ----D---- C:\WINDOWS\system32\config
2010-07-26 20:44:00 ----D---- C:\WINDOWS\AppPatch
2010-07-26 20:43:57 ----D---- C:\Program Files\Common Files
2010-07-26 19:56:46 ----RASHC---- C:\boot.ini
2010-07-22 14:15:16 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-07-21 15:08:03 ----D---- C:\Program Files\uTorrent

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 agp440;Intel AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-13 42368]
R0 AVGIDSErHrxpx;AVG9IDSErHr; C:\WINDOWS\System32\Drivers\AVGIDSxx.sys [2010-07-19 25168]
R0 AvgRkx86;avgrkx86.sys; C:\WINDOWS\System32\Drivers\avgrkx86.sys [2010-07-19 52872]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-07 43528]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2008-01-18 77696]
R1 AvgLdx86;AVG AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2010-07-19 216400]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2010-07-19 29584]
R1 AvgTdiX;AVG Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2010-07-19 243024]
R1 GhPciScan;GhostPciScanner; \??\C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys []
R2 Aspi32;Aspi32; C:\WINDOWS\system32\drivers\Aspi32.sys [2002-08-14 17005]
R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2009-02-06 55152]
R2 zumbus;Zune Bus Enumerator Driver; C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-11-10 40832]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816]
R3 Avgfwdx;Avgfwdx; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2010-07-19 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver; \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys []
R3 AVGIDSFilterxpx;AVG9IDSFilter; \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys []
R3 AVGIDSShimxpx;AVG9IDSShim; \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys []
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2008-04-17 15464]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2006-04-12 49664]
R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2006-04-12 16496]
R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2006-04-12 21568]
R3 ltmodem5;LT Modem Driver; C:\WINDOWS\system32\DRIVERS\ltmdmnt.sys [2004-08-03 606684]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 MXOPSWD;Maxtor OneTouch Security Driver; C:\WINDOWS\system32\DRIVERS\mxopswd.sys [2007-05-03 22152]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-12-10 3536768]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2008-12-09 47360]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2006-02-08 9856]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2002-05-28 500568]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
S1 nvport;NVIDIA PORT IO Control Driver; \??\C:\WINDOWS\system32\Drivers\nvport.sys []
S3 Avgfwfd;AVG network filter service; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2010-07-19 30104]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 DM9102;DAVICOM 9102(A) PCI Fast Ethernet Based NT Driver; C:\WINDOWS\system32\DRIVERS\DM9PCI5.SYS [2001-08-17 29696]
S3 dot4;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2008-04-13 206976]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
S3 Dot4Scan;Scan Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Scan.sys [2001-08-17 8704]
S3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2001-08-17 23808]
S3 DVxplore;NVTV; C:\WINDOWS\system32\DRIVERS\DVxplore.sys [2004-09-07 75776]
S3 E100B;Intel® PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-08-17 117760]
S3 MHNDRV;MHN driver; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-10 11008]
S3 MREMP50;MREMP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS []
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []
S3 MRESP50;MRESP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS []
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 netwg311;NETGEAR WG311v2 802.11g Wireless PCI Adapter; C:\WINDOWS\system32\DRIVERS\netwg311.sys [2004-06-18 386688]
S3 ngrpci;NETGEAR FA310TX Fast Ethernet Adapter Driver; C:\WINDOWS\system32\DRIVERS\ngrpci.sys [2001-08-17 32840]
S3 Point32;Microsoft IntelliPoint Filter Driver; C:\WINDOWS\system32\DRIVERS\point32.sys [2008-06-10 31048]
S3 RTL8023xp;TRENDnet 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2007-06-28 95488]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-13 12288]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2008-10-01 32000]
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 usbbus;LGE CDMA Composite USB Device; C:\WINDOWS\system32\DRIVERS\lgusbbus.sys [2005-05-26 21344]
S3 USBModem;LGE CDMA USB Modem; C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys [2005-06-24 39036]
S3 VX1000;VX-1000; C:\WINDOWS\system32\DRIVERS\VX1000.sys [2007-04-10 1966312]
S3 WinUSB;WinUSB; C:\WINDOWS\system32\DRIVERS\WinUSB.sys [2006-11-02 39368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-10-01 116040]
R2 avg9wd;AVG WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2010-07-19 308136]
R2 avgfws9;AVG Firewall; C:\Program Files\AVG\AVG9\avgfws9.exe [2010-07-19 2331032]
R2 ehRecvr;Media Center Receiver Service; C:\WINDOWS\eHome\ehRecvr.exe [2006-04-09 237568]
R2 ehSched;Media Center Scheduler Service; C:\WINDOWS\eHome\ehSched.exe [2005-08-05 102912]
R2 GhostStartService;GhostStartService; C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe [2002-08-14 200704]
R2 Maxtor Sync Service;Maxtor Service; C:\Program Files\Maxtor\Sync\SyncServices.exe [2008-07-21 193888]
R2 McciCMService;McciCMService; C:\Program Files\Common Files\Motive\McciCMService.exe [2008-11-18 303104]
R2 McrdSvc;Media Center Extender Service; C:\WINDOWS\ehome\mcrdsvc.exe [2005-08-05 99328]
R2 MSCamSvc;MSCamSvc; C:\Program Files\Microsoft LifeCam\MSCamS32.exe [2007-05-17 271720]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2005-12-10 131139]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2006-03-03 69632]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-05-14 249136]
R2 SimpTcp;Simple TCP/IP Services; C:\WINDOWS\system32\tcpsvcs.exe [2006-03-15 19456]
R2 SNMP;SNMP Service; C:\WINDOWS\System32\snmp.exe [2008-04-13 33280]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
R2 YahooAUService;Yahoo! Updater; C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe [2008-11-09 602392]
R2 ZuneBusEnum;Zune Bus Enumerator; C:\WINDOWS\system32\ZuneBusEnum.exe [2008-12-12 60032]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-10-01 536872]
S2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe []
S2 avg9emc;AVG E-mail Scanner; C:\Program Files\AVG\AVG9\avgemc.exe [2010-07-20 921952]
S2 AVGIDSAgent;AVG9IDSAgent; C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2010-07-19 5897808]
S2 gupdate1c9d023e4b4b290;Google Update Service (gupdate1c9d023e4b4b290); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-05-08 133104]
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-08 183280]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 fsssvc;Windows Live Family Safety; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 getPlus® Helper;getPlus® Helper; C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2008-08-29 33752]
S3 HP Port Resolver;HP Port Resolver; C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE [2005-05-20 81920]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SNMPTRAP;SNMP Trap Service; C:\WINDOWS\System32\snmptrap.exe [2008-04-13 8704]
S3 ZuneNetworkSvc;Zune Network Sharing Service; C:\Program Files\Zune\ZuneNss.exe [2008-12-12 5117568]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service; C:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-12-12 243840]
S4 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-10-09 724992]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]

-----------------EOF-----------------

DDS (Ver_10-03-17.01) - NTFSx86
Run by jada at 10:13:52.81 on Fri 08/20/2010
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_03
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.767.138 [GMT -7:00]

AV: AVG Internet Security *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *disabled* {8decf618-9569-4340-b34a-d78d28969b66}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\vVX1000.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\AVG\AVG9\avgfws9.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
D:\Jada\Downloads\dds.scr

============== Pseudo HJT Report ===============

uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.15642\swg.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn1\YTSingleInstance.dll
TB: AVG Security Toolbar: {a057a204-bacc-4d26-9990-79a187e2698e} - c:\progra~1\avg\avg8\AVGTOO~1.DLL
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [mxomssmenu] "c:\program files\maxtor\onetouch status\maxmenumgr.exe"
mRun: [nwiz] nwiz.exe /install
mRun: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe"
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [LifeCam] "c:\program files\microsoft lifecam\LifeExp.exe"
mRun: [VX1000] c:\windows\vVX1000.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: ingdirect.com\banking
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\jada\applic~1\mozilla\firefox\profiles\uefe5p4n.default\
FF - plugin: c:\documents and settings\jada\local settings\application data\yahoo!\browserplus\2.6.0\plugins\npybrowserplus_2.6.0.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, falsec:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");

============= SERVICES / DRIVERS ===============

R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [2010-7-19 25168]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2010-7-19 52872]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-4-25 216400]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2007-3-19 29584]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-4-25 243024]
R1 GhPciScan;GhostPciScanner;c:\program files\symantec\norton ghost 2003\GhPciScan.sys [2002-8-14 5632]
R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-7-19 308136]
R2 avgfws9;AVG Firewall;c:\program files\avg\avg9\avgfws9.exe [2010-7-19 2331032]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-7-27 55152]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2010-7-19 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSDriver.sys [2010-7-19 122448]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSFilter.sys [2010-7-19 30288]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSShim.sys [2010-7-19 26192]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe --> c:\progra~1\avg\avg8\avgwdsvc.exe [?]
S2 avg9emc;AVG E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-7-19 921952]
S2 AVGIDSAgent;AVG9IDSAgent;c:\program files\avg\avg9\identity protection\agent\bin\AVGIDSAgent.exe [2010-7-19 5897808]
S2 gupdate1c9d023e4b4b290;Google Update Service (gupdate1c9d023e4b4b290);c:\program files\google\update\GoogleUpdate.exe [2009-5-8 133104]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2010-7-19 30104]
S3 DVxplore;NVTV;c:\windows\system32\drivers\DVxplore.sys [2004-9-7 75776]
S3 fsssvc;Windows Live Family Safety;c:\program files\windows live\family safety\fsssvc.exe [2009-2-6 533360]
S3 ngrpci;NETGEAR FA310TX Fast Ethernet Adapter Driver;c:\windows\system32\drivers\Ngrpci.sys [2007-3-22 32840]

=============== Created Last 30 ================

2010-08-20 16:59:10 0 d-----w- c:\program files\trend micro
2010-07-27 02:56:38 0 dcsha-r- C:\cmdcons
2010-07-27 02:53:42 98816 ----a-w- c:\windows\sed.exe
2010-07-27 02:53:42 77312 ----a-w- c:\windows\MBR.exe
2010-07-27 02:53:42 256512 ----a-w- c:\windows\PEV.exe
2010-07-27 02:53:42 161792 ----a-w- c:\windows\SWREG.exe
2010-07-22 21:02:25 0 d-----w- c:\docume~1\jada\applic~1\AVG9

==================== Find3M ====================

2010-07-20 02:34:26 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-07-20 02:34:21 52872 -c--a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-07-20 02:34:21 25168 -c--a-w- c:\windows\system32\drivers\AVGIDSxx.sys
2010-07-20 02:34:20 243024 -c--a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-20 02:34:14 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-07-20 02:29:29 50968 ----a-w- c:\windows\system32\avgfwdx.dll
2010-07-20 02:29:29 30104 ----a-w- c:\windows\system32\drivers\avgfwdx.sys
2010-07-19 17:44:00 1652688 ----a-w- c:\windows\is-5LMDP.tmp
2010-06-30 12:31:35 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 12:15:28 832512 ----a-w- c:\windows\system32\wininet.dll
2010-06-24 12:15:26 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-06-24 12:15:26 17408 ----a-w- c:\windows\system32\corpol.dll
2010-06-23 13:44:04 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-17 14:03:00 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 07:41:45 1172480 ----a-w- c:\windows\system32\msxml3.dll
2008-11-15 03:45:15 32768 -csha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008111420081115\index.dat

============= FINISH: 10:14:52.59 ===============

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-08-20 11:59:10
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\jada\LOCALS~1\Temp\uwlciaod.sys


---- System - GMER 1.0.15 ----

SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xF698D670]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0xF698D720]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xF698D7C0]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xF698D860]

---- Kernel code sections - GMER 1.0.15 ----

.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF65FB360, 0x20598D, 0xE8000020]

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat AVGIDSFilter.sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )

---- EOF - GMER 1.0.15 ----


#4 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:04:55 AM

Posted 21 August 2010 - 09:27 AM

QUOTE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

Did you have the various antivirus programs and firewalls installed at some time?
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#5 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:04:55 AM

Posted 21 August 2010 - 09:30 AM

The item(s) below indicate(s) you have installed .

"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"

Since the nature of P2P programs are counter productive to restoring your PC to a healthy state, I ask that you remove P2P file sharing programs prior to my providing you with malware removal assistance. Even the safest P2P file sharing programs that do not contain bundled spyware, still expose you to risks because of the very nature of the P2P file sharing process. By default, most P2P file sharing programs are configured to automatically launch at startup. They are also configured to allow other P2P users on the same network open access to a shared directory on your computer.

The people who design and distribute malware will use any method to infect personal computers to make use of their stored data or machine power for further propagation of the malware files. A popular method is the use of file-sharing tools as a tremendous amount of prospective victims can be reached through it. Many very malicious worms and trojans, such as the Storm Worm, target and spread across P2P files sharing networks because of their known vulnerabilities.
To remove the P2P program:
  1. Click Start > Control Panel.
  2. In Control Panel, double-click Add or Remove Programs.
  3. In Add or Remove Programs, highlight , click Remove.
  4. Close the Add or Remove Programs and the Control Panel windows.
  5. Using Windows Explorer (Windows key+e), search for the folder. If the program folder is still there, select/highlight . DELETE it. (File > Delete.) If Windows is not installed on the C drive, replace C:\ with the appropriate drive letter.
  6. Close Windows Explorer.
There is a Video showing how to uninstall a program (Grinler) detailing how to add or remove program in Windows for those who find a visual aid appealing. NOTE: Take care when answering any questions posed by an uninstaller. Some questions may be worded to deceive you into keeping the program.

I am not asking you to do remove the P2P program(s) without giving you good reasons for doing so.
  1. P2P programs form a direct conduit on to your computer.
  2. P2P security measures are easily circumvented.
  3. Some P2P programs will share everything on the computer with anyone by default. If your P2P program is not configured correctly, you may be sharing more files than you realize.
  4. There have been cases where people's passwords, address books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured program.
  5. P2P programs have always been a target of malware writers. There are more Viruses, Worms and Trojans being distributed with the downloaded files.
  6. P2P programs connected to a network can be used to spread malware, share private documents, or use the file server to both store and forward malware.
  7. Many of the files in P2P networks are copyrighted and legal action could result.
  8. Pedophiles can use P2P communities to distribute child porn materials or attempt to make contact with children.
  9. This article from InfoWorld, Seattle Man Arrested For P To P ID Theft, illustrates perfectly the dangers of a poorly configured P2P program.
  10. Many of the programs come bundled with other unwanted programs, but even the ones free of any bundled software are not safe to use.
  11. When you use them, you are downloading software from an unknown source directly onto your computer bypassing your Firewall and Anti-Virus software. Many of these Downloads are being targeted to carry infections.

References for the risk of these programs are:If you continue to use P2P programs, you will probably get infected again.

Please uninstall all P2P programs and post a new HijackThis log.

You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#6 Salamander Huner

Salamander Huner
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:55 AM

Posted 21 August 2010 - 05:40 PM

Hi,. Thanks for your quick response. I do not recognize any of those antivirus programs or firewalls, and I did not ever have them running (intentionally); I generally use AVG, I have used Mcafee and Norton in the past...

I did my best to remove all Utorrent files and folders to find that there were a chunk of small .dat files that are seemingly write protected and irremovable...here is what one looks like (unfortunately cut/paste doesn't seem to work here, and upon scrolling through them, most of the list has disappeared; suspect):

~UTorrentPartFile_1DD68821A.dat

Anyway, I ran the RSIT utility again and here is the log file (Thanks!):

Logfile of random's system information tool 1.08 (written by random/random)
Run by jada at 2010-08-21 15:30:17
Microsoft Windows XP Professional Service Pack 3
System drive C: has 1 GB (5%) free of 21 GB
Total RAM: 767 MB (30% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:30:44 PM, on 8/21/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17080)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\vVX1000.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\AVG\AVG9\avgfws9.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\Jada\Downloads\RSIT.exe
C:\Program Files\trend micro\jada.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase5483.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (file missing)
O23 - Service: AVG E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: AVG Firewall (avgfws9) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgfws9.exe
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: Google Update Service (gupdate1c9d023e4b4b290) (gupdate1c9d023e4b4b290) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 10490 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Google Software Updater.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\Microsoft_Hardware_Launch_IPoint_exe.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
&Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll [2010-03-23 940856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG9\avgssie.dll [2010-07-20 1619296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-05-14 191792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll [2007-09-25 501136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll [2009-08-08 669168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
SingleInstance Class - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll [2010-03-23 160056]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{A057A204-BACC-4D26-9990-79A187E2698E} - AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL []
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll [2010-03-23 940856]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2005-12-10 7311360]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2008-09-06 413696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-10-01 289576]
"mxomssmenu"=C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe [2008-07-21 169312]
"nwiz"=nwiz.exe /install []
"Zune Launcher"=C:\Program Files\Zune\ZuneLauncher.exe [2008-12-12 157312]
"itype"=C:\Program Files\Microsoft IntelliType Pro\itype.exe [2008-06-10 1442888]
"IntelliPoint"=C:\Program Files\Microsoft IntelliPoint\ipoint.exe [2008-06-10 1406024]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"LifeCam"=C:\Program Files\Microsoft LifeCam\LifeExp.exe [2007-05-17 279912]
"VX1000"=C:\WINDOWS\vVX1000.exe [2007-04-10 709992]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"AVG9_TRAY"=C:\PROGRA~1\AVG\AVG9\avgtray.exe [2010-07-19 2065760]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-05-08 39408]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
C:\WINDOWS\ehome\ehtray.exe [2005-08-05 64512]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-02-19 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mxomssmenu]
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe [2008-07-21 169312]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\WINDOWS\system32\NvCpl.dll [2005-12-10 7311360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\system32\NvMcTray.dll [2005-12-10 86016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe [2008-01-23 26112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe [2007-09-25 132496]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE [1999-11-04 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2006-02-19 288472]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqthb08.exe [2006-02-10 73728]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
C:\PROGRA~1\INTERV~1\Common\Bin\WINCIN~1.EXE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^jada^Start Menu^Programs^Startup^Microsoft Office Groove.lnk]
C:\PROGRA~1\MICROS~2\Office12\GROOVE.EXE [2009-02-14 337264]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^jada^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
C:\PROGRA~1\MICROS~2\Office12\ONENOTEM.EXE [2009-02-26 97680]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3
"Pml Driver HPZ12"=2
"ose"=3
"odserv"=3
"NBService"=3
"Microsoft Office Groove Audit Service"=3
"HP Status Server"=3
"HP Port Resolver"=3

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2010-07-19 12536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-13 239616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\AIM\aim.exe"="C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\AVG\AVG9\avgam.exe"="C:\Program Files\AVG\AVG9\avgam.exe:*:Enabled:avgam.exe"
"C:\Program Files\AVG\AVG9\avgdiagex.exe"="C:\Program Files\AVG\AVG9\avgdiagex.exe:*:Enabled:avgdiagex.exe"
"C:\Program Files\AVG\AVG9\avgemc.exe"="C:\Program Files\AVG\AVG9\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\AVG\AVG9\avgupd.exe"="C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG9\avgnsx.exe"="C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

======List of files/folders created in the last 1 months======

2010-08-20 09:59:10 ----D---- C:\Program Files\trend micro
2010-08-20 09:59:09 ----DC---- C:\rsit
2010-08-12 22:17:27 ----SHDC---- C:\RECYCLER
2010-08-11 12:25:26 ----HDC---- C:\WINDOWS\$NtUninstallKB982214$
2010-08-11 12:24:59 ----HDC---- C:\WINDOWS\$NtUninstallKB981852$
2010-08-11 12:24:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2079403$
2010-08-11 12:13:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2160329$
2010-08-11 12:12:44 ----HDC---- C:\WINDOWS\$NtUninstallKB980436$
2010-08-11 12:04:11 ----HDC---- C:\WINDOWS\$NtUninstallKB981997$
2010-08-11 12:02:57 ----HDC---- C:\WINDOWS\$NtUninstallKB982665$
2010-08-03 12:00:59 ----HDC---- C:\WINDOWS\$NtUninstallKB2286198$
2010-07-26 20:57:26 ----AC---- C:\ComboFix.txt
2010-07-26 20:13:42 ----ASH---- C:\hiberfil.sys
2010-07-26 19:56:45 ----AC---- C:\Boot.bak
2010-07-26 19:56:38 ----RASHDC---- C:\cmdcons
2010-07-26 19:53:42 ----A---- C:\WINDOWS\zip.exe
2010-07-26 19:53:42 ----A---- C:\WINDOWS\SWXCACLS.exe
2010-07-26 19:53:42 ----A---- C:\WINDOWS\SWSC.exe
2010-07-26 19:53:42 ----A---- C:\WINDOWS\SWREG.exe
2010-07-26 19:53:42 ----A---- C:\WINDOWS\sed.exe
2010-07-26 19:53:42 ----A---- C:\WINDOWS\PEV.exe
2010-07-26 19:53:42 ----A---- C:\WINDOWS\NIRCMD.exe
2010-07-26 19:53:42 ----A---- C:\WINDOWS\MBR.exe
2010-07-26 19:53:42 ----A---- C:\WINDOWS\grep.exe
2010-07-26 19:53:21 ----D---- C:\WINDOWS\ERDNT
2010-07-26 19:49:06 ----ADC---- C:\Qoobox
2010-07-26 19:35:11 ----A---- C:\WINDOWS\ntbtlog.txt
2010-07-22 14:02:25 ----D---- C:\Documents and Settings\jada\Application Data\AVG9

======List of files/folders modified in the last 1 months======

2010-08-21 15:28:31 ----D---- C:\WINDOWS\Prefetch
2010-08-21 15:24:30 ----D---- C:\Program Files
2010-08-21 15:10:45 ----D---- C:\Program Files\Mozilla Firefox
2010-08-21 12:27:10 ----SD---- C:\WINDOWS\Tasks
2010-08-21 09:51:48 ----D---- C:\WINDOWS\Temp
2010-08-21 08:41:06 ----A---- C:\WINDOWS\ModemLog_Lucent Win Modem.txt
2010-08-20 21:00:13 ----DC---- C:\Documents and Settings\All Users\Application Data\Google Updater
2010-08-20 09:50:58 ----D---- C:\WINDOWS\Registration
2010-08-20 09:50:30 ----D---- C:\WINDOWS
2010-08-20 09:50:05 ----D---- C:\WINDOWS\system32
2010-08-19 21:55:21 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-08-18 16:13:46 ----D---- C:\WINDOWS\system32\drivers\Avg
2010-08-18 09:52:46 ----D---- C:\WINDOWS\system32\CatRoot2
2010-08-11 13:35:15 ----D---- C:\WINDOWS\Microsoft.NET
2010-08-11 13:34:40 ----RSD---- C:\WINDOWS\assembly
2010-08-11 12:59:59 ----DC---- C:\Config.Msi
2010-08-11 12:28:02 ----HD---- C:\WINDOWS\inf
2010-08-11 12:27:22 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-08-11 12:26:59 ----D---- C:\WINDOWS\system32\en-US
2010-08-11 12:26:56 ----D---- C:\Program Files\Internet Explorer
2010-08-11 12:26:33 ----D---- C:\WINDOWS\ie7updates
2010-08-11 12:25:38 ----D---- C:\WINDOWS\system32\drivers
2010-08-11 12:25:37 ----A---- C:\WINDOWS\imsins.BAK
2010-08-11 12:25:21 ----HD---- C:\WINDOWS\$hf_mig$
2010-08-11 12:24:10 ----SHD---- C:\WINDOWS\Installer
2010-08-11 12:24:02 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2010-08-11 12:19:55 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-08-11 12:18:58 ----D---- C:\WINDOWS\WinSxS
2010-08-11 12:04:14 ----D---- C:\Program Files\Movie Maker
2010-08-11 10:45:55 ----D---- C:\WINDOWS\system32\CatRoot
2010-08-03 11:09:31 ----A---- C:\WINDOWS\system32\MRT.exe
2010-07-26 23:30:35 ----A---- C:\WINDOWS\system32\shell32.dll
2010-07-26 20:51:07 ----AC---- C:\WINDOWS\system.ini
2010-07-26 20:50:41 ----D---- C:\WINDOWS\system32\drivers\etc
2010-07-26 20:47:40 ----D---- C:\WINDOWS\system32\config
2010-07-26 20:44:00 ----D---- C:\WINDOWS\AppPatch
2010-07-26 20:43:57 ----D---- C:\Program Files\Common Files
2010-07-26 19:56:46 ----RASHC---- C:\boot.ini
2010-07-22 14:15:16 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 agp440;Intel AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-13 42368]
R0 AVGIDSErHrxpx;AVG9IDSErHr; C:\WINDOWS\System32\Drivers\AVGIDSxx.sys [2010-07-19 25168]
R0 AvgRkx86;avgrkx86.sys; C:\WINDOWS\System32\Drivers\avgrkx86.sys [2010-07-19 52872]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2007-03-07 43528]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2008-01-18 77696]
R1 AvgLdx86;AVG AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2010-07-19 216400]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2010-07-19 29584]
R1 AvgTdiX;AVG Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2010-07-19 243024]
R1 GhPciScan;GhostPciScanner; \??\C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys []
R2 Aspi32;Aspi32; C:\WINDOWS\system32\drivers\Aspi32.sys [2002-08-14 17005]
R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2009-02-06 55152]
R2 zumbus;Zune Bus Enumerator Driver; C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-11-10 40832]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816]
R3 Avgfwdx;Avgfwdx; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2010-07-19 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver; \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys []
R3 AVGIDSFilterxpx;AVG9IDSFilter; \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys []
R3 AVGIDSShimxpx;AVG9IDSShim; \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys []
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2008-04-17 15464]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2006-04-12 49664]
R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2006-04-12 16496]
R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2006-04-12 21568]
R3 ltmodem5;LT Modem Driver; C:\WINDOWS\system32\DRIVERS\ltmdmnt.sys [2004-08-03 606684]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 MXOPSWD;Maxtor OneTouch Security Driver; C:\WINDOWS\system32\DRIVERS\mxopswd.sys [2007-05-03 22152]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-12-10 3536768]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2008-12-09 47360]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2006-02-08 9856]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2002-05-28 500568]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
S1 nvport;NVIDIA PORT IO Control Driver; \??\C:\WINDOWS\system32\Drivers\nvport.sys []
S3 Avgfwfd;AVG network filter service; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2010-07-19 30104]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 DM9102;DAVICOM 9102(A) PCI Fast Ethernet Based NT Driver; C:\WINDOWS\system32\DRIVERS\DM9PCI5.SYS [2001-08-17 29696]
S3 dot4;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2008-04-13 206976]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
S3 Dot4Scan;Scan Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Scan.sys [2001-08-17 8704]
S3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2001-08-17 23808]
S3 DVxplore;NVTV; C:\WINDOWS\system32\DRIVERS\DVxplore.sys [2004-09-07 75776]
S3 E100B;Intel® PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-08-17 117760]
S3 MHNDRV;MHN driver; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-10 11008]
S3 MREMP50;MREMP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS []
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []
S3 MRESP50;MRESP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS []
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 netwg311;NETGEAR WG311v2 802.11g Wireless PCI Adapter; C:\WINDOWS\system32\DRIVERS\netwg311.sys [2004-06-18 386688]
S3 ngrpci;NETGEAR FA310TX Fast Ethernet Adapter Driver; C:\WINDOWS\system32\DRIVERS\ngrpci.sys [2001-08-17 32840]
S3 Point32;Microsoft IntelliPoint Filter Driver; C:\WINDOWS\system32\DRIVERS\point32.sys [2008-06-10 31048]
S3 RTL8023xp;TRENDnet 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2007-06-28 95488]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-13 12288]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2008-10-01 32000]
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 usbbus;LGE CDMA Composite USB Device; C:\WINDOWS\system32\DRIVERS\lgusbbus.sys [2005-05-26 21344]
S3 USBModem;LGE CDMA USB Modem; C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys [2005-06-24 39036]
S3 uwlciaod;uwlciaod; \??\C:\DOCUME~1\jada\LOCALS~1\Temp\uwlciaod.sys []
S3 VX1000;VX-1000; C:\WINDOWS\system32\DRIVERS\VX1000.sys [2007-04-10 1966312]
S3 WinUSB;WinUSB; C:\WINDOWS\system32\DRIVERS\WinUSB.sys [2006-11-02 39368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-10-01 116040]
R2 avg9wd;AVG WatchDog; C:\Program Files\AVG\AVG9\avgwdsvc.exe [2010-07-19 308136]
R2 avgfws9;AVG Firewall; C:\Program Files\AVG\AVG9\avgfws9.exe [2010-07-19 2331032]
R2 ehRecvr;Media Center Receiver Service; C:\WINDOWS\eHome\ehRecvr.exe [2006-04-09 237568]
R2 ehSched;Media Center Scheduler Service; C:\WINDOWS\eHome\ehSched.exe [2005-08-05 102912]
R2 GhostStartService;GhostStartService; C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe [2002-08-14 200704]
R2 Maxtor Sync Service;Maxtor Service; C:\Program Files\Maxtor\Sync\SyncServices.exe [2008-07-21 193888]
R2 McciCMService;McciCMService; C:\Program Files\Common Files\Motive\McciCMService.exe [2008-11-18 303104]
R2 McrdSvc;Media Center Extender Service; C:\WINDOWS\ehome\mcrdsvc.exe [2005-08-05 99328]
R2 MSCamSvc;MSCamSvc; C:\Program Files\Microsoft LifeCam\MSCamS32.exe [2007-05-17 271720]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2005-12-10 131139]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-05-14 249136]
R2 SimpTcp;Simple TCP/IP Services; C:\WINDOWS\system32\tcpsvcs.exe [2006-03-15 19456]
R2 SNMP;SNMP Service; C:\WINDOWS\System32\snmp.exe [2008-04-13 33280]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
R2 YahooAUService;Yahoo! Updater; C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe [2008-11-09 602392]
R2 ZuneBusEnum;Zune Bus Enumerator; C:\WINDOWS\system32\ZuneBusEnum.exe [2008-12-12 60032]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-10-01 536872]
S2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe []
S2 avg9emc;AVG E-mail Scanner; C:\Program Files\AVG\AVG9\avgemc.exe [2010-07-20 921952]
S2 AVGIDSAgent;AVG9IDSAgent; C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2010-07-19 5897808]
S2 gupdate1c9d023e4b4b290;Google Update Service (gupdate1c9d023e4b4b290); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-05-08 133104]
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-08 183280]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2006-03-03 69632]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 fsssvc;Windows Live Family Safety; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 getPlus® Helper;getPlus® Helper; C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2008-08-29 33752]
S3 HP Port Resolver;HP Port Resolver; C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE [2005-05-20 81920]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SNMPTRAP;SNMP Trap Service; C:\WINDOWS\System32\snmptrap.exe [2008-04-13 8704]
S3 ZuneNetworkSvc;Zune Network Sharing Service; C:\Program Files\Zune\ZuneNss.exe [2008-12-12 5117568]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service; C:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-12-12 243840]
S4 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-10-09 724992]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]

-----------------EOF-----------------




#7 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:04:55 AM

Posted 22 August 2010 - 11:22 AM

NOTE: If for some reason you are unable to complete a step(s), skip that step and continue with the rest of the steps. Please describe your problem with the step in your next reply.

Step 1

You may want to print this page. Make sure to work through the fixes in the order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes.

Step 2

Ensure that you have the latest version of Java Runtime Environment which is currently Java Runtime Environment Version 6 Update 21 (jre-6u21. If you do not have the latest version, follow the instructions below.

Remove the older versions of Java Runtime Environment. Older versions have vulnerabilities that malware can use to infect your system.
  • Close any programs you may have running, ESPECIALLY your web browser
  • Click Start > Control Panel.
  • Click Add/Remove Programs.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove all versions of Java.
  • Reboot your computer after all Java components are removed.
Download the latest version.
  1. Click java.com download page.
  2. Under
    QUOTE
    Java Downloads for All Operating Systems
    Recommended Version 6 Update 21
    scroll down to Windows and click on Windows XP/Vista/2000/2003 Offline.
  3. NOTE: This page offers files for different platforms - please be sure to download the proper file(s) for your platform.
  4. The File Download dialog box appears. Choose the folder location. (Save the file to a known location on your computer, for example, to your desktop).
  5. Click Save.
  6. If you have previously downloaded this version of JRE, you may be prompted:
    QUOTE
    File jre-6ux-windows-i586.exe already exists. Do you want to replace it?
  7. Click Yes to replace.
  8. Verify that the:
    QUOTE
    Name of the file is jre-6u21-windows-i586.exe
    Size is approximately 13.8 MB
  9. Close all applications including the browser.
  10. Double-click on the saved file icon to start the installation process.
    The installer unpacks the files needed for the installation, which takes less than a minute. After unpacking the installation files, a welcome screen is displayed, the installer presents an option to view the license agreement. Choose Accept the license agreement to continue the installation process
  11. Note: Sun Microsystems has partnered with companies that offer various products. The installer may present you with option to install these programs when you install JRE. Make your selections by clicking on the check box next to programs that interest you.
  12. Click on Next to continue the installation.
  13. The installer displays a Custom Setup screen that allows you to choose program features to set up. We recommend that you keep the default settings unless you are an advanced user who wants more precise control over the components that will be installed.
  14. After ensuring that the desired program features are selected, click the Next button to continue with the installation.
  15. To test that the JRE is installed, enabled and working properly on your computer, run this test applet from our web site: verify Java has been installed correctly..
Step 3

TFC (Temp File Cleaner) will clear out all temp folders for all user accounts (temp, IE temp, java, FF, Opera, Chrome, Safari), including Administrator, All Users, LocalService, NetworkService, and any other accounts in the user folder. It also cleans out the %systemroot%\temp folder and checks for .tmp files in the %systemdrive% root folder, %systemroot%, and the system32 folder (both 32bit and 64bit on 64bit OSs). It shows the amount removed for each location found (in bytes) and the total removed (in MB). Before running, it will stop Explorer and all other running apps. When finished, if a reboot is required the user must reboot to finish clearing any in-use temp files.

TFC only cleans temp folders. TFC will not clean URL history, prefetch, or cookies. Depending on how often someone cleans their temp folders, their system hardware, and how many accounts are present, it can take anywhere from a few seconds to a minute or more. TFC will completely clear all temp files where other temp file cleaners may fail. TFC requires a reboot immediately after running. Be sure to save any unsaved work before running TFC.
  1. Please download TFC by OldTimer to your desktop.
  2. Open the file and close any other windows.
  3. It will close all programs itself when run; make sure to let it run uninterrupted.
  4. Click the Start button to begin the process. The program should not take long to finish its job.
  5. After it is finished, it should reboot your machine, if not, do this yourself to ensure a complete clean.
Step 4

In normal mode, run an online antivirus check from at least two and preferably three of the following sites
BitDefender
Computer Associates Online Virus Scan
Panda's ActiveScan
Trend Micro Housecall
Windows Live Safety Center Free Online Scan
This scanner from Trend does not require an Active X to run.
  1. Detects and removes malware ( viruses, worms, trojans, etc. )
  2. Detects and removes grayware and spyware
  3. Restores damage caused by malware to your system.
  4. Notifies about vulnerabilities in installed programs and connected network services.
  5. Multi-platform support for: Windows, Linux, Solaris.
  6. Easy-to-use with the Microsoft Internet Explorer and Mozilla Firefox.
When you have completed the scans, if you get a report of files that can’t be cleaned / deleted, make a note of the file location of anything that cannot be deleted so you can delete it yourself. Please post that list in your next reply.

Step 4

Please download Spybot-S&D©® and install Spybot-S&D©® .
  1. Be sure to UNCHECK TeaTimer when presented with the option to install. You can enable it after you are clean.
  2. Run Spybot-S&D©® , go to the Menu Bar at the top choose Mode and make certain that "Default mode" has a check mark beside it.
  3. Click the button "Search for Updates".
  4. If any updates are found, install them by placing a check mark next to each one and clicking "Download Updates".
  5. If you encounter any error messages while downloading the updates, manually download them from here.
  6. Click on "Immunize". When it detects what has or has not been blocked, block all remaining items by clicking the green plus sign next to immunize at the top.
  7. Click the button "Check for Problems".
  8. When Spybot-S&D©® is complete, it will be showing RED entries, bold BLACK entries and GREEN entries in the window.
  9. Make certain there is a check mark beside all of the RED entries ONLY.
  10. Choose "Fix Selected Problems" and allow Spybot-S&D©® to fix the RED entries.
  11. REBOOT to complete the scan and clear memory.
Note: After Windows loads, Spybot-S&D©® may run again to clean some files that it could not clean during the prior session. Follow the same procedure.

Step 5

I recommend using SpywareBlaster.
  • Please download SpywareBlaster and save it to your desktop.
  • Double click on it to install the program.
  • Follow the prompts and choose the default locations when installing the program.
  • When the program is installed, it will place an icon on your desktop.
  • Double click on the SpywareBlaster icon and you will be presented with a brief tutorial. On the first page of this tutorial, you will see some of the SpywareBlaster features
  • Click on the Next button to proceed to the second page of the tutorial.
  • If you want to purchase the software, then you should select Automatic Updating. If you do not plan on purchasing the software, then you should select the option for Manual Updating. Press the Next button.
  • At the next screen, click Finish.
  • At the next screen, Protection Status, click Enable All Protection.
  • Click Download Latest Protection Updates. This will ensure that SpywareBlaster has the latest definitions so that it can protect your browser more efficiently. You should update SpywareBlaster regularly, as much as every few days, in order to provide the best protection. Each time you update, be sure to click Enable All Protection.
Step 6

Malwarebytes' Anti-Malware is FREEWARE, however you may upgrade to the PRO version which contains realtime protection, scheduled scanning and updating.
  1. Please download Malwarebytes Anti-Malware (MBAM). Alternate download link
  2. Double-click on Download_mbam-setup.exe to install the application.
  3. When the installation begins, follow the prompts and do not make any changes to default settings.
  4. When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  5. Click Finish.
  6. MBAM will automatically start and you will be asked to update the program before performing scan. If an update is found, the program will automatically update itself.
  7. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from the Malware Bytes Web site. Scroll down the page until you see Latest Database; click Download from GT500.org
  8. Double-click on mbam-rules.exe to install.
  9. On the Scanner tab, make sure the Perform Quick Scan option is selected.
  10. Click on the Scan button.
  11. If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  12. The scan will begin and Scan in progress will show at the top. It may take some time to complete; please be patient.
  13. When the scan is finished, a message box will say "The scan completed successfully.
  14. At the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  15. Make sure that everything is checked, and click Remove Selected.
  16. When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  17. The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  18. Copy and paste the contents of that report in your next reply and exit MBAM.
  19. Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.
Step 7
  1. Please download SUPERAntiSpyware (SAS) - SUPERAntiSpyware Free Version For Home Users
  2. Install it and double-click the icon on your desktop to run it.
  3. It will ask if you want to update the program definitions, click Yes.
  4. Under Configuration and Preferences, click the Preferences button.
  5. Click the Scanning Control tab.
  6. Under Scanner Options, make sure the following are checked:
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
    • Please leave the others unchecked.
  7. Click the Close button to leave the control center screen.
  8. On the main screen, under Scan for Harmful Software, click Scan your computer.
  9. On the left, check C:\Fixed Drive.
  10. On the right, under Complete Scan, choose Perform Complete Scan.
  11. Click Next to start the scan. Please be patient while it scans your computer.
  12. After the scan is complete, a summary box will appear. Click OK.
  13. Make sure everything in the white box has a check next to it, then click Next.
  14. It will quarantine what it found and if it asks if you want to reboot, click Yes.
  15. To retrieve the removal information, please do the following:
    • After reboot, double-click the SUPERAntispyware icon on your desktop.
    • Click Preferences. Click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • It will open in your default text editor (such as Notepad/Wordpad).
    • Please highlight everything in the notepad, then right-click and choose Copy.
    • Click Close and Close again to exit the program.
  16. Please post that information with a new HijackThis log.

SUPERAntiSpyware Advice:

CAUTION: SuperAntiSpyware comes with a program called Bootsafe, do not for any reason use this program, if used on an infected computer, it could render it UNBOOTABLE.

Step 8

We need to disconnect your computer from the Internet. By doing this, it prevents any further Internet activity until the removal of malware is complete. You need to make it impossible for viruses, trojan horses, worms and spyware to call for backup once you start to dismantle them. They will continue to infect your computer with new variants while you are connected to the Internet. We also need to prevent hackers from controlling your system and they will try to prevent you from removing the pests they installed on your computer.

Close ALL browser windows (including this one). Exit all processes and items in your System tray.

According to how your computer connects to the Internet, please disconnect your computer from the Internet. Possible means of disconnecting your computer from the Internet include:
  • Physically remove the cable for your broadband Internet service “Always On” Connection from your computer.
  • Turn your modem off.
  • Disconnect your modem cable from your computer.
  • Turn the device off for Hand-held wireless connections.
  • Some laptops have a switch that will disconnect the laptop from the Internet.
Step 9

During the process of removing malware from your computer, there are times you may need to use specialized fix tools. Certain embedded files that are part of these specialized fix tools may be detected by your antivirus or anti-malware scanner as a RiskTool, Hacking tool, Potentially unwanted tool, a virus or a Trojan when that is not the case.
These tools have been carefully created and tested by security experts so if your antivirus or anti-malware program flags them as malware, then it is a False Positive. Antivirus scanners cannot distinguish between good and malicious use of such programs; therefore, they may alert you or even automatically remove them. In these cases, the removal of these files can have unpredictable results and unintentional results.
To avoid any problems while using a specialized fix tool, it is very important that you temporarily disable your antivirus and/or anti-malware programs before using the specialized fix tool.
When your system has been cleaned, it is important that you enable your security programs to avoid reinfection.
Please disable the following program(s):

SUPERAntiSpyware

We need to disable SUPERAntiSpyware as it may interfere with the fixes that we need to make.
  1. Right click on the icon in your System Tray.
  2. Click Exit
  3. Make sure that the program, SUPERAntiSpyware itself, is also closed/not running.
Step 10

Now we will address the HijackThis fixes.
  1. If you have not already done so, please download Trend Micro - HijackThis.
  2. Double click HJTInstall.exe to begin installation.
  3. Accept the installation location, which by default is C:\Program Files\Trend Micro\HijackThis or click the Browse... button if you want to save it in another location.
  4. Click Install.
  5. A shortcut will be created on your Desktop and HijackThis will run automatically.
  6. Click the button labeled Do a system scan only.
  7. Click the Scan button in the lower left hand corner of the interface and HijackThis will quickly scan your system.
  8. Click in the boxes to the left of the following entries to place check marks (make sure not to miss any):

    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)
    O23 - Service: AVG Free8 WatchDog (avg8wd) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (file missing)

  9. Close all browsers and other windows except for HijackThis, and click Fix Checked to have HijackThis fix the entries you checked.
Step 11

Optional Fixes is the name that we use for fixes for unnecessary programs that load during startup and run in the background. These programs are not required to start automatically as you can start them manually if you need them. You would be removing the program from your startup but you would not be removing the program itself.

Your computer may be sluggish due to the many programs loading during startup and running in the background that are not necessary. Windows has a facility for starting programs at startup time. Some of these programs are required for your computer and the applications installed on it to run correctly. A good example of such a program is a virus-checking application that must always run, constantly checking for and isolating or removing files with viruses. Other such programs are not strictly required, or are optional. In some cases, you can gain significant performance enhancements by disabling the automatic startup of these programs. In many cases, the functionality offered by the programs is still available by starting the programs manually by, for example, starting the program from the Windows Start->Programs menu. Media players and instant messaging programs often fall into this category. In fact, it is common for many modern software applications, when installed, to add programs at startup that add items to the system tray or shortcut (context) menus in Windows Explorer to provide quick access to the features and functions of these applications. While they may be useful, they do increase boot time and consume system resources. It is advised that you disable these programs so that they do not take up necessary resources or slow the boot time.

Other than ScanRegistry, SystemTray, StateMgr, antivirus program entries, and firewall program entries, very few others need to load and run.

Read the articles below to see if it applies to your computer problem with being slow to respond.
Slow Computer/browser? Check Here First; It May Not Be Malware
What to do if your Computer is running slowly
Help! My computer is slow!
50 Tips for a Super Fast PC
4 Ways to Speed Up Your Computer's Performance
It's not always malware: How to fix the top 10 Internet Explorer issues

If you decide that you want to stop the Optional Fixes in your startup, let me know and I will give you a list with instructions. You would be removing the program from your startup but you would not be removing the program itself.

Step 12

Please download and scan with Dr.Web CureIt. Follow the instructions here for performing a scan in "Safe Mode" .
-- Post the log in your next reply.

Perform an anti-rootkit (ARK) scan with one of the following:
Before performing an ARK scan it is recommended to do the following to ensure more accurate results and avoid common issues that may cause false detections.
  1. Disconnect from the Internet or physically unplug your Internet cable connection.
  2. Clean out your temporary files.
  3. Close all open programs, scheduling/updating tasks and background processes that might activate during the scan including the screensaver.
  4. Temporarily disable your anti-virus and real-time anti-spyware protection.
  5. After starting the scan, do not use the computer until the scan has completed.
  6. When finished, enable your anti-virus/anti-malware (or reboot) and then you can reconnect to the Internet.

Note: Not all hidden components detected by ARKs are malicious. It is normal for a Firewall, some Anti-virus and Anti-malware software (ProcessGuard, Prevx1, AVG AS), sandboxes, virtual machines and Host based Intrusion Prevention Systems (HIPS) to hook into the OS kernal/SSDT in order to protect your system. You should not be alarmed if you see any hidden entries created by these software programs after performing a scan.

Step 13

Check to see if you have insecure applications with
Secunia Software Inspector. Secunia Software Inspector:
  1. Detects insecure versions of common/popular programs installed on your computer.
  2. Verifies that all Microsoft patches are applied.
  3. Assists you in updating, patching, and protecting your computer.
  4. Activates additional security features in Sun Java.
  5. Runs through your browser. No installation or download is required.
Step 14

Please run HijackThis in Normal Mode and post a new HijackThis log so I can make sure that all the malware was deleted according to plan.

Please post:
  1. the list of file names and locations for any files that cannot be cleaned / deleted that were reported after you completed the online scans.
  2. the log from MalwareBytes
  3. the log from SUPERAntiSpyware
  4. a new HijackThis log
Please advise me of any problems you still have.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#8 Salamander Huner

Salamander Huner
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:55 AM

Posted 25 August 2010 - 02:08 PM

Thank you for your patience! That was Fun! Each step seemed to run smoothly. Spyware Blaster found and deleted the tracking cookie, and Dr Web found and deleted the trojans(3 files, maybe 9 objects total). I couldn't seem to attain logs for the Spyware Blaster or the Dr. Web; Here are the requested logs:


Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4327

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11

8/22/2010 6:51:46 PM
mbam-log-2010-08-22 (18-51-46).txt

Scan type: Quick scan
Objects scanned: 144106
Time elapsed: 8 minute(s), 11 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 08/22/2010 at 09:13 PM

Application Version : 4.41.1000

Core Rules Database Version : 5392
Trace Rules Database Version: 3204

Scan type : Complete Scan
Total Scan Time : 01:06:55

Memory items scanned : 462
Memory threats detected : 0
Registry items scanned : 8928
Registry threats detected : 0
File items scanned : 27221
File threats detected : 466

Adware.Tracking Cookie
C:\Documents and Settings\jada\Cookies\jada@atwola[2].txt
C:\Documents and Settings\jada\Cookies\jada@cdn.at.atwola[2].txt
C:\Documents and Settings\jada\Cookies\jada@questionmarket[1].txt
C:\Documents and Settings\jada\Cookies\jada@247realmedia[2].txt
C:\Documents and Settings\jada\Cookies\jada@ar.atwola[1].txt
C:\Documents and Settings\jada\Cookies\jada@tribalfusion[2].txt
C:\Documents and Settings\jada\Cookies\jada@bs.serving-sys[2].txt
C:\Documents and Settings\jada\Cookies\jada@imrworldwide[2].txt
C:\Documents and Settings\jada\Cookies\jada@tacoda[2].txt
C:\Documents and Settings\jada\Cookies\jada@a1.interclick[1].txt
C:\Documents and Settings\jada\Cookies\jada@insightexpressai[2].txt
C:\Documents and Settings\jada\Cookies\jada@content.yieldmanager[2].txt
C:\Documents and Settings\jada\Cookies\jada@oasn04.247realmedia[1].txt
C:\Documents and Settings\jada\Cookies\jada@realmedia[2].txt
C:\Documents and Settings\jada\Cookies\jada@edge.ru4[1].txt
C:\Documents and Settings\jada\Cookies\jada@webstat.pge[3].txt
C:\Documents and Settings\jada\Cookies\jada@yieldmanager[1].txt
C:\Documents and Settings\jada\Cookies\jada@collective-media[1].txt
C:\Documents and Settings\jada\Cookies\jada@specificmedia[1].txt
C:\Documents and Settings\jada\Cookies\jada@socialmedia[1].txt
C:\Documents and Settings\jada\Cookies\jada@content.yieldmanager[3].txt
C:\Documents and Settings\jada\Cookies\jada@at.atwola[1].txt
C:\Documents and Settings\jada\Cookies\jada@avgtechnologies.112.2o7[1].txt
C:\Documents and Settings\jada\Cookies\jada@serving-sys[2].txt
C:\Documents and Settings\jada\Cookies\jada@ads.bridgetrack[1].txt
C:\Documents and Settings\jada\Cookies\jada@ads.pointroll[2].txt
C:\Documents and Settings\jada\Cookies\jada@webstat.pge[2].txt
C:\Documents and Settings\jada\Cookies\jada@msnportal.112.2o7[1].txt
C:\Documents and Settings\jada\Cookies\jada@interclick[2].txt
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
stat.dealtime.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.revsci.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.pornhub.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.pornhub.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.delivery.trafficjunky.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
www.pornhub.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
www.pornhub.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.msnportal.112.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
webstat.pge.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
webstat.pge.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.roiservice.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.imrworldwide.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.imrworldwide.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
click.eventful.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
sales.liveperson.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.dmtracker.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
stat.onestat.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
stat.onestat.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.nextag.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.nextag.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.nextag.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.nextag.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
link.mercent.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
server.iad.liveperson.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.dealtime.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.thefind.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.thefind.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.thefind.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.thefind.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.bizrate.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.bizrate.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.media6degrees.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.media6degrees.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.media6degrees.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.media6degrees.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.ru4.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.ru4.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.ru4.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.ru4.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
sales.liveperson.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.hearstmagazines.112.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.andomedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.ru4.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.ru4.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
sales.liveperson.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.examinercom.122.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.thumbplay.112.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.web-stat.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.web-stat.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.web-stat.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
stat.onestat.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
stat.onestat.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
stat.onestat.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
stat.onestat.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
stat.onestat.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.roiservice.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.capemaycountyherald.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.capemaycountyherald.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.media.causes.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.care2.112.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
stat.onestat.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.pornex.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.naiadsystems.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.medhelpinternational.112.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.ru4.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.ru4.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.pornhub.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.foxinteractivemedia.122.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
www.womens-health-questions.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
www.womens-health-questions.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
traffic.prod.cobaltgroup.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.bzresults.122.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.kango.112.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.commonsensemedia.org [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.commonsensemedia.org [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.commonsensemedia.org [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.cracked.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.cracked.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.ru4.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.carfax.112.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
server.iad.liveperson.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
banner.foxylayouts.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.ru4.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.ru4.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.netclickpartners.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.overture.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.overture.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.americancancersocietyinc.112.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.rentalfindersite.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
web4.realtracker.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
pluckit.demandmedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.tripod.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.adecn.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
e.k.e.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.adserving.contextualmarketplace.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.adserving.contextualmarketplace.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.edge.ru4.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.edge.ru4.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.edge.ru4.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.edge.ru4.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.edge.ru4.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.questionmarket.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.interclick.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.interclick.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.a1.interclick.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.pointroll.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.pointroll.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.ads.pointroll.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.at.atwola.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.tacoda.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.tacoda.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.tacoda.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.at.atwola.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.at.atwola.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.media6degrees.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.specificclick.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.specificclick.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.specificclick.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.specificclick.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.specificmedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
cdn4.specificclick.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
cdn4.specificclick.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.collective-media.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.specificclick.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
f.w.e.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.adxpose.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.bs.serving-sys.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.serving-sys.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
f.u.e.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.adtech.de [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.adinterax.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.adinterax.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.atwola.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.realmedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.realmedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.realmedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
s.m.e.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
www.burstbeacon.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.media6degrees.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
y.k.e.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
z.i.e.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.specificclick.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
cdn4.specificclick.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
cdn4.specificclick.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
cdn4.specificclick.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
cdn4.specificclick.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
u.u.q.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.myxer.adbureau.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.myxer.adbureau.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.myxer.adbureau.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.myxer.adbureau.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.myxer.adbureau.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.tribalfusion.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.myxer.adbureau.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.realmedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.247realmedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.network.realmedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
cdn4.specificclick.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.specificclick.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
b.v.q.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
ad.reduxmedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
ad.reduxmedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
ads.bridgetrack.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
cdn4.specificclick.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.a1.interclick.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
tracking.admarketplace.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.pro-market.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.adserver.adtechus.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.ru4.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.chitika.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
in.getclicky.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
j.v.q.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
j.w.q.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.yieldmanager.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.legolas-media.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.kontera.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.kontera.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.kontera.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.overture.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.marriottinternational.122.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
stat.onestat.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.traveladvertising.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.hotelscom.122.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
rotator.adjuggler.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
rotator.adjuggler.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
l.h.q.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
l.m.q.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
l.o.q.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.adcentriconline.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.kontera.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.247realmedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.247realmedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.247realmedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
x.w.q.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.interclick.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
myaccount.verizonwireless.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.liveperson.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.liveperson.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.crackle.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.redorbit.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.redorbit.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.crackle.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.crackle.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.crackle.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.crackle.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.redorbit.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.redorbit.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
dc.tremormedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
eas.apm.emediate.eu [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.lstat.youku.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.lstat.youku.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.ru4.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.ru4.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trvlnet.adbureau.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trvlnet.adbureau.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trvlnet.adbureau.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
cdn4.specificclick.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
1.p.y.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
www.homemediamagazine.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.homemediamagazine.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.homemediamagazine.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
www.homemediamagazine.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
b.v.y.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.adultfriendfinder.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.adultfriendfinder.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.invitemedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.traveladvertising.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trvlnet.adbureau.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
k.l.y.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
k.v.y.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.associatedcontent.112.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
adserver.avalonsunsplash.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
r.l.y.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
r.k.y.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.insightexpressai.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
r.n.y.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.liveperson.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
4.m.y.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.adlegend.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.adlegend.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
y.m.y.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
adserverus.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.fortunecity.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.fortunecity.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.fortunecity.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
0.l.y.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.legolas-media.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.legolas-media.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
n.v.i.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.clicksor.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.clicksor.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.clicksor.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.clicksor.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.clicksor.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.primediabusiness.122.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
webanalytics.crownpeak.com.re.getclicky.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.liveperson.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.specificclick.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
o.q.i.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.adserver9.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.adserver9.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
stat.onestat.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
v.p.i.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
w.k.i.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
www.adfluxmedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
www.adfluxmedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
www.adfluxmedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
w.l.i.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.tripod.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
3.q.i.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.revsci.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
c.w.i.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
c.u.i.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
d.o.i.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.ru4.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.realmedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.track.tester-rewards.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.track.tester-rewards.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.xm.xtendmedia.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
d.p.i.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
j.w.i.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
j.u.i.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
k.q.i.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.questionmarket.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.adserve.amazingrewardsonline.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.adserve.amazingrewardsonline.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.trafficmp.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.pornhublive.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.walmart.112.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
stats.gamestop.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
stats.gamestop.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
g.k.i.cltomedia.info [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
banner.adchemy.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
banner.adchemy.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.avgtechnologies.112.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.popularscreensavers.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.popularscreensavers.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.fullscreensavers.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.fullscreensavers.com [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.microsoftwga.112.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.bonniercorp.122.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.cbs.112.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.revsci.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.revsci.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
server.iad.liveperson.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.liveperson.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.msnservices.112.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.microsoftwindows.112.2o7.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.revsci.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.revsci.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]
.revsci.net [ C:\Documents and Settings\jada\Application Data\Mozilla\Firefox\Profiles\uefe5p4n.default\cookies.sqlite ]

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:55:25 AM, on 8/25/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17080)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\vVX1000.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\trend micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase5483.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: Google Update Service (gupdate1c9d023e4b4b290) (gupdate1c9d023e4b4b290) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 9646 bytes


Is it Ok for me to defrag now?


#9 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:04:55 AM

Posted 28 August 2010 - 05:03 PM

Wait on Defragmenting until the computer is clear. Please post a new HijackThis log.

Please run HijackThis and click Scan. Place checks next to the following entries (make sure not to miss any):

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL (file missing)


Close all browsers and other windows except for HijackThis, and click Fix Checked to have HijackThis fix the entries you checked.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#10 Salamander Huner

Salamander Huner
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:55 AM

Posted 28 August 2010 - 07:29 PM

Hi, Thank you for your response.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:26:04 PM, on 8/28/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17080)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\vVX1000.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\trend micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase5483.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: Google Update Service (gupdate1c9d023e4b4b290) (gupdate1c9d023e4b4b290) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 9299 bytes




Logfile of random's system information tool 1.08 (written by random/random)
Run by jada at 2010-08-28 17:24:05
Microsoft Windows XP Professional Service Pack 3
System drive C: has 291 MB (1%) free of 21 GB
Total RAM: 767 MB (57% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:24:31 PM, on 8/28/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17080)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Zune\ZuneLauncher.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\WINDOWS\vVX1000.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\jada\Desktop\Downloads\RSIT.exe
C:\Program Files\trend micro\jada.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase5483.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - Unknown owner - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: Google Update Service (gupdate1c9d023e4b4b290) (gupdate1c9d023e4b4b290) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 9341 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Google Software Updater.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\WINDOWS\tasks\Microsoft_Hardware_Launch_IPoint_exe.job
C:\WINDOWS\tasks\WebReg Photosmart C5100 series.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-05-14 191792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll [2009-08-08 669168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-08-22 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-08-22 79648]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2005-12-10 7311360]
"mxomssmenu"=C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe [2008-07-21 169312]
"nwiz"=nwiz.exe /install []
"Zune Launcher"=C:\Program Files\Zune\ZuneLauncher.exe [2008-12-12 157312]
"itype"=C:\Program Files\Microsoft IntelliType Pro\itype.exe [2008-06-10 1442888]
"IntelliPoint"=C:\Program Files\Microsoft IntelliPoint\ipoint.exe [2008-06-10 1406024]
"LifeCam"=C:\Program Files\Microsoft LifeCam\LifeExp.exe [2007-05-17 279912]
"VX1000"=C:\WINDOWS\vVX1000.exe [2007-04-10 709992]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-05-14 248552]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2010-06-19 35760]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-06-09 976832]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2010-07-21 141608]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2010-08-10 421888]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-05-08 39408]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2010-08-26 2424560]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
C:\WINDOWS\ehome\ehtray.exe [2005-08-05 64512]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-02-19 49152]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mxomssmenu]
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe [2008-07-21 169312]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\WINDOWS\system32\NvCpl.dll [2005-12-10 7311360]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\system32\NvMcTray.dll [2005-12-10 86016]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
C:\Program Files\Real\RealPlayer\RealPlay.exe [2008-01-23 26112]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE [1999-11-04 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2006-02-19 288472]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Photosmart Premier Fast Start.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqthb08.exe [2006-02-10 73728]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
C:\PROGRA~1\INTERV~1\Common\Bin\WINCIN~1.EXE []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^jada^Start Menu^Programs^Startup^Microsoft Office Groove.lnk]
C:\PROGRA~1\MICROS~2\Office12\GROOVE.EXE [2009-02-14 337264]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^jada^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
C:\PROGRA~1\MICROS~2\Office12\ONENOTEM.EXE [2009-02-26 97680]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3
"Pml Driver HPZ12"=2
"ose"=3
"odserv"=3
"NBService"=3
"Microsoft Office Groove Audit Service"=3
"HP Status Server"=3
"HP Port Resolver"=3

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [2009-09-03 548352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-13 239616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\AIM\aim.exe"="C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour Service"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"

======List of files/folders created in the last 1 months======

2010-08-26 12:47:31 ----D---- C:\WINDOWS\LastGood
2010-08-25 11:36:48 ----D---- C:\Program Files\iPod
2010-08-25 11:36:27 ----DC---- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-08-25 11:36:27 ----D---- C:\Program Files\iTunes
2010-08-25 11:31:03 ----D---- C:\Program Files\Apple Software Update
2010-08-25 11:27:09 ----D---- C:\Program Files\Bonjour
2010-08-25 00:59:06 ----D---- C:\Program Files\Winamp Detect
2010-08-24 13:16:53 ----ASH---- C:\hiberfil.sys
2010-08-24 13:13:21 ----N---- C:\WINDOWS\system32\1.tmp
2010-08-24 13:13:09 ----D---- C:\Program Files\Sophos
2010-08-22 19:54:09 ----DC---- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2010-08-22 19:54:09 ----D---- C:\Documents and Settings\jada\Application Data\SUPERAntiSpyware.com
2010-08-22 19:53:59 ----D---- C:\Program Files\SUPERAntiSpyware
2010-08-22 18:20:16 ----ADC---- C:\Documents and Settings\All Users\Application Data\TEMP
2010-08-22 18:20:11 ----D---- C:\Program Files\SpywareBlaster
2010-08-22 13:12:25 ----D---- C:\Documents and Settings\jada\Application Data\QuickScan
2010-08-22 12:22:11 ----D---- C:\Program Files\Panda Security
2010-08-22 12:10:56 ----DC---- C:\Documents and Settings\All Users\Application Data\Sun
2010-08-22 12:10:54 ----D---- C:\Program Files\Common Files\Java
2010-08-22 12:10:16 ----A---- C:\WINDOWS\system32\javaws.exe
2010-08-22 12:10:16 ----A---- C:\WINDOWS\system32\javaw.exe
2010-08-22 12:10:16 ----A---- C:\WINDOWS\system32\java.exe
2010-08-22 12:10:16 ----A---- C:\WINDOWS\system32\deployJava1.dll
2010-08-20 09:59:10 ----D---- C:\Program Files\trend micro
2010-08-20 09:59:09 ----DC---- C:\rsit
2010-08-12 22:17:27 ----SHDC---- C:\RECYCLER
2010-08-11 12:25:26 ----HDC---- C:\WINDOWS\$NtUninstallKB982214$
2010-08-11 12:24:59 ----HDC---- C:\WINDOWS\$NtUninstallKB981852$
2010-08-11 12:24:31 ----HDC---- C:\WINDOWS\$NtUninstallKB2079403$
2010-08-11 12:13:03 ----HDC---- C:\WINDOWS\$NtUninstallKB2160329$
2010-08-11 12:12:44 ----HDC---- C:\WINDOWS\$NtUninstallKB980436$
2010-08-11 12:04:11 ----HDC---- C:\WINDOWS\$NtUninstallKB981997$
2010-08-11 12:02:57 ----HDC---- C:\WINDOWS\$NtUninstallKB982665$
2010-08-03 12:00:59 ----HDC---- C:\WINDOWS\$NtUninstallKB2286198$

======List of files/folders modified in the last 1 months======

2010-08-28 17:24:04 ----D---- C:\WINDOWS\Prefetch
2010-08-28 17:21:58 ----D---- C:\Program Files\Mozilla Firefox
2010-08-28 16:52:29 ----A---- C:\WINDOWS\NeroDigital.ini
2010-08-28 14:40:10 ----SD---- C:\WINDOWS\Tasks
2010-08-28 06:45:00 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-08-27 12:36:06 ----D---- C:\WINDOWS\Temp
2010-08-27 08:58:09 ----A---- C:\WINDOWS\ModemLog_Lucent Win Modem.txt
2010-08-26 21:40:14 ----DC---- C:\Documents and Settings\All Users\Application Data\Google Updater
2010-08-26 12:54:43 ----D---- C:\WINDOWS
2010-08-26 12:51:35 ----SHD---- C:\WINDOWS\Installer
2010-08-26 12:51:35 ----DC---- C:\Config.Msi
2010-08-26 12:50:56 ----A---- C:\WINDOWS\win.ini
2010-08-26 12:50:38 ----D---- C:\WINDOWS\system32
2010-08-26 12:50:06 ----D---- C:\WINDOWS\twain_32
2010-08-26 12:48:19 ----HD---- C:\WINDOWS\inf
2010-08-26 12:47:30 ----D---- C:\WINDOWS\system32\CatRoot2
2010-08-26 12:33:56 ----D---- C:\WINDOWS\Registration
2010-08-25 11:53:40 ----DC---- C:\Documents and Settings\All Users\Application Data\Adobe
2010-08-25 11:47:38 ----D---- C:\Program Files\QuickTime
2010-08-25 11:37:46 ----D---- C:\WINDOWS\system32\drivers
2010-08-25 11:37:45 ----DC---- C:\WINDOWS\system32\DRVSTORE
2010-08-25 11:36:48 ----D---- C:\Program Files
2010-08-25 11:36:45 ----D---- C:\Program Files\Common Files\Apple
2010-08-25 11:24:55 ----D---- C:\Program Files\Common Files\Adobe
2010-08-25 01:55:28 ----D---- C:\Documents and Settings\jada\Application Data\Winamp
2010-08-25 01:00:17 ----D---- C:\Program Files\Winamp
2010-08-22 23:46:33 ----A---- C:\WINDOWS\ntbtlog.txt
2010-08-22 23:37:24 ----SD---- C:\Documents and Settings\jada\Application Data\Microsoft
2010-08-22 18:27:18 ----DC---- C:\Documents and Settings\All Users\Application Data\avg9
2010-08-22 16:51:05 ----D---- C:\WINDOWS\system32\drivers\etc
2010-08-22 12:10:54 ----D---- C:\Program Files\Common Files
2010-08-22 12:09:48 ----D---- C:\Program Files\Java
2010-08-22 11:58:09 ----D---- C:\Program Files\Yahoo!
2010-08-11 13:35:15 ----D---- C:\WINDOWS\Microsoft.NET
2010-08-11 13:34:40 ----RSD---- C:\WINDOWS\assembly
2010-08-11 12:28:02 ----A---- C:\WINDOWS\imsins.BAK
2010-08-11 12:27:22 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-08-11 12:26:59 ----D---- C:\WINDOWS\system32\en-US
2010-08-11 12:26:56 ----D---- C:\Program Files\Internet Explorer
2010-08-11 12:26:33 ----D---- C:\WINDOWS\ie7updates
2010-08-11 12:25:21 ----HD---- C:\WINDOWS\$hf_mig$
2010-08-11 12:24:02 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2010-08-11 12:19:55 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-08-11 12:18:58 ----D---- C:\WINDOWS\WinSxS
2010-08-11 12:04:14 ----D---- C:\Program Files\Movie Maker
2010-08-11 10:45:55 ----D---- C:\WINDOWS\system32\CatRoot
2010-08-03 11:09:31 ----A---- C:\WINDOWS\system32\MRT.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 agp440;Intel AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agp440.sys [2008-04-13 42368]
R0 PxHelp20;PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [2009-04-28 44944]
R0 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2008-01-18 77696]
R1 GhPciScan;GhostPciScanner; \??\C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS []
R2 Aspi32;Aspi32; C:\WINDOWS\system32\drivers\Aspi32.sys [2002-08-14 17005]
R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2009-02-06 55152]
R2 zumbus;Zune Bus Enumerator Driver; C:\WINDOWS\system32\DRIVERS\zumbus.sys [2008-11-10 40832]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2006-04-12 49664]
R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2006-04-12 16496]
R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2006-04-12 21568]
R3 ltmodem5;LT Modem Driver; C:\WINDOWS\system32\DRIVERS\ltmdmnt.sys [2004-08-03 606684]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 MXOPSWD;Maxtor OneTouch Security Driver; C:\WINDOWS\system32\DRIVERS\mxopswd.sys [2007-05-03 22152]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-12-10 3536768]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2008-12-09 47360]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2006-02-08 9856]
R3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2002-05-28 500568]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 Wdf01000;Kernel Mode Driver Frameworks service; C:\WINDOWS\System32\Drivers\wdf01000.sys [2008-03-27 503008]
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
S1 nvport;NVIDIA PORT IO Control Driver; \??\C:\WINDOWS\system32\Drivers\nvport.sys []
S1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 DM9102;DAVICOM 9102(A) PCI Fast Ethernet Based NT Driver; C:\WINDOWS\system32\DRIVERS\DM9PCI5.SYS [2001-08-17 29696]
S3 dot4;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2008-04-13 206976]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
S3 Dot4Scan;Scan Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Scan.sys [2001-08-17 8704]
S3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2001-08-17 23808]
S3 DVxplore;NVTV; C:\WINDOWS\system32\DRIVERS\DVxplore.sys [2004-09-07 75776]
S3 E100B;Intel® PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-08-17 117760]
S3 MEMSWEEP2;MEMSWEEP2; \??\C:\WINDOWS\system32\5.tmp []
S3 MHNDRV;MHN driver; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-10 11008]
S3 MREMP50;MREMP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50.SYS []
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS []
S3 MRESP50;MRESP50 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50.SYS []
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS []
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 netwg311;NETGEAR WG311v2 802.11g Wireless PCI Adapter; C:\WINDOWS\system32\DRIVERS\netwg311.sys [2004-06-18 386688]
S3 ngrpci;NETGEAR FA310TX Fast Ethernet Adapter Driver; C:\WINDOWS\system32\DRIVERS\ngrpci.sys [2001-08-17 32840]
S3 Point32;Microsoft IntelliPoint Filter Driver; C:\WINDOWS\system32\DRIVERS\point32.sys [2008-06-10 31048]
S3 RTL8023xp;TRENDnet 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2007-06-28 95488]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-13 12288]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2008-10-01 32000]
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 usbbus;LGE CDMA Composite USB Device; C:\WINDOWS\system32\DRIVERS\lgusbbus.sys [2005-05-26 21344]
S3 USBModem;LGE CDMA USB Modem; C:\WINDOWS\system32\DRIVERS\lgusbmodem.sys [2005-06-24 39036]
S3 VX1000;VX-1000; C:\WINDOWS\system32\DRIVERS\VX1000.sys [2007-04-10 1966312]
S3 WinUSB;WinUSB; C:\WINDOWS\system32\DRIVERS\WinUSB.sys [2006-11-02 39368]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-01-18 83328]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2010-06-10 144176]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2010-05-18 345376]
R2 ehRecvr;Media Center Receiver Service; C:\WINDOWS\eHome\ehRecvr.exe [2006-04-09 237568]
R2 ehSched;Media Center Scheduler Service; C:\WINDOWS\eHome\ehSched.exe [2005-08-05 102912]
R2 GhostStartService;GhostStartService; C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe [2002-08-14 200704]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2010-08-22 153376]
R2 Maxtor Sync Service;Maxtor Service; C:\Program Files\Maxtor\Sync\SyncServices.exe [2008-07-21 193888]
R2 McciCMService;McciCMService; C:\Program Files\Common Files\Motive\McciCMService.exe [2008-11-18 303104]
R2 McrdSvc;Media Center Extender Service; C:\WINDOWS\ehome\mcrdsvc.exe [2005-08-05 99328]
R2 MSCamSvc;MSCamSvc; C:\Program Files\Microsoft LifeCam\MSCamS32.exe [2007-05-17 271720]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2005-12-10 131139]
R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-05-14 249136]
R2 SimpTcp;Simple TCP/IP Services; C:\WINDOWS\system32\tcpsvcs.exe [2006-03-15 19456]
R2 SNMP;SNMP Service; C:\WINDOWS\System32\snmp.exe [2008-04-13 33280]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
R2 YahooAUService;Yahoo! Updater; C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe [2008-11-09 602392]
R2 ZuneBusEnum;Zune Bus Enumerator; C:\WINDOWS\system32\ZuneBusEnum.exe [2008-12-12 60032]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2010-07-21 540968]
S2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe []
S2 gupdate1c9d023e4b4b290;Google Update Service (gupdate1c9d023e4b4b290); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-05-08 133104]
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-08 183280]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2006-03-03 69632]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 fsssvc;Windows Live Family Safety; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S3 getPlus® Helper;getPlus® Helper; C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2008-08-29 33752]
S3 HP Port Resolver;HP Port Resolver; C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE [2005-05-20 81920]
S3 HP Status Server;HP Status Server; C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE [2004-10-16 73728]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SNMPTRAP;SNMP Trap Service; C:\WINDOWS\System32\snmptrap.exe [2008-04-13 8704]
S3 ZuneNetworkSvc;Zune Network Sharing Service; C:\Program Files\Zune\ZuneNss.exe [2008-12-12 5117568]
S3 ZuneWlanCfgSvc;Zune Wireless Configuration Service; C:\WINDOWS\system32\ZuneWlanCfgSvc.exe [2008-12-12 243840]
S4 NBService;NBService; C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2006-10-09 724992]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]

-----------------EOF-----------------



#11 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:04:55 AM

Posted 30 August 2010 - 04:53 PM

I do not see any obvious signs of malware. How is your computer behaving now?
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.

#12 Salamander Huner

Salamander Huner
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:55 AM

Posted 30 August 2010 - 05:22 PM

I am not seeing any obvious malfunctions or clunkiness...
I am wondering now what I might want to do to better protect my system from future threats. I know I can run malwarbytes and Spybot periodically but (now that I have removed AVG) what software offers more continuous protection...I know I don't want Spybot's tea timer for example, and AVG doesn't seem to cut it...Any advice here?

#13 suebaby41

suebaby41

    W.A.M. (Women Against Malware)


  • Malware Response Team
  • 6,248 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:South Carolina, USA
  • Local time:04:55 AM

Posted 30 August 2010 - 05:31 PM




You may be interested in Freeware Replacements For Common Commercial Apps.

Tips To Protect Your Computer
  • Avoid clicking on links in instant messages.
  • Avoid opening email attachments.
  • Avoid visiting every poker site on the net.
  • Avoid downloading all that free cute junk.
  • Avoid using the peer-to-peer file sharing.
  • Avoid getting those handy toolbar doodads for your browsers.
  • Malware is out there just waiting to pounce on your system if you only pass by where they are lurking which may be at some seemingly innocent web site. Be careful because some of the malware are so vicious that no one can possibly save you once you let them in.
  • Remember that new malware emerges every week of the year. Take responsibility for protecting your system because you are its first and best defense.

Tools Downloaded To Clean Your Computer

I may have asked you to install some tools. Whether or not you need to keep these programs must be decided by you. If you choose to uninstall them, follow these directions:
  1. Click Start > Control Panel.
  2. In Control Panel, double-click Add or Remove Programs.
  3. In Add or Remove Programs, highlight the program, click Remove.
  4. Close the Add or Remove Programs and the Control Panel windows.
Optional Tools:
  1. ATF-Cleaner cleans all user temp folders, Java cache, (which seems to be harboring more and more malware), the cache, cookies, history, download history, visited links and saved passwords. Scan weekly if you have high Internet use.
  2. Trend Micro's HijackThis or random's System Information Tool (RSIT) may be uninstalled; however, if you should ever encounter another problem and seek help in this forum or others like it, you will need to download this application.
  3. SUPERAntiSpyware scans, detects, and removes spyware on your computer.
  4. Malwarebytes ' Anti-Malware scans, detects, and removes malware on your computer.
  5. a-squared Free scans, detects, and removes trojans, worms, spyware on your computer.
  6. Spybot S&D scans, detects, and removes malware on your computer.
If you have changed the default settings for files/folders, please restore the default settings for files/folders.
  1. Go to My Computer.
  2. Select the Tools menu and click Folder Options.
  3. Click the View tab.
  4. Under Advanced Settings, click the Restore Defaults button in the lower right corner.
  5. Click Apply and then the OK and close My Computer.
Please take the time to read the "Steps To Keep Your Computer Clean And Secure" below.

STEPS TO KEEP YOUR COMPUTER CLEAN AND SECURE:

Please follow these simple steps in order to keep your computer clean and secure:
  1. Disable and Enable System Restore. After cleaning, you will need to disable the System Restore function For Windows XP.
    Files placed in the System volume information folder are source files for the System Restore function that is available in Windows XP operating system. Files that were healed were moved in their original INFECTED state into this folder and it is necessary to DELETE them by following these steps:
    1. Close all open programs. Then right-click My Computer on the Windows' desktop
    2. Click on Properties.
    3. Click on the System Restore tab.
    4. Check Turn off System Restore on all drives.
    5. Restart the system.
    6. Enable System Restore by going through the first four steps again and uncheck the item mentioned in Step d.
    7. You can find instructions on how to disable and enable system restore in the Windows XP System Restore Guide.
  2. Make your Internet Explorer more secure: This can be done by following these simple instructions:
    1. From within Internet Explorer click on the Tools menu and then click on Options.
    2. Click once on the Security tab
    3. Click once on the Internet icon so it becomes highlighted.
    4. Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub frames across different domains to Prompt
    5. When all these settings have been made, click on the OK button.
    6. If it asks you if you want to save the settings, press the Yes button.
    7. Click Apply > OK button and then the OK to exit the Internet Properties page.
  3. Use a Firewall: - I cannot stress how important it is that you use a Firewall on your computer.  Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For an article on Firewalls and a listing of some available ones see the link below:
    Computer Safety On line - Software Firewalls. For more information about firewalls, and why a two-way firewall is better than the Windows XP one-way firewall, please read Understanding and Using Firewalls.
  4. Use An Antivirus Software and Keep It Updated: - It is very important that your computer has an antivirus software running on your machine.  This alone can save you a lot of trouble with malware in the future.  It is imperative that you update your antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software, then it will not be able to catch any of the new variants that may come out. For an article on antivirus programs and a listing of some available ones see the link below:
    Computer Safety On line - Anti-Virus
  5. Visit Microsoft's Windows Update Site Frequently: It is important that you visit Microsoft Windows Update regularly. This will ensure your computer has the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
  6. You should scan your computer with Spybot S&D on a regular basis just as you would an anti- virus software. A tutorial on installing & using this product can be found here:
    Using Spybot - Search & Destroy to remove Spyware from Your Computer
  7. Update SpywareBlaster (at least weekly): SpywareBlaster will add a large list of programs and sites into your Internet Explorer and Firec settings that will protect you from running and downloading known malicious programs. An article on anti-malware products with links for this program and others can be found here:
    Computer Safety on line Anti Malware
  8. Use the hosts file: Every version of windows has a hosts file as part of them. In a very basic sense, they are used to locate web pages. We can customize a hosts file so that it blocks certain web pages. However, it can slow down certain computers. This is why using a hosts file is optional. Download mvps hosts file Make sure you read the instructions on how to install the hosts file. There is a good tutorial HERE If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
    1. Click the start button on the task bar at the bottom of your screen
    2. Click run
    3. In the dialog box, type services.msc
    4. hit enter, then locate dns client
    5. Highlight it, then doubleclick it.
    6. On the dropdown box, change the setting from automatic to manual.
    7. Click OK.
  9. Use an alternative instant messenger program:.Trillian and Miranda IM These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)
  10. Please read Tony Klein's excellent article: How I got Infected in the First Place
  11. Please read Understanding Spyware, Browser Hijackers, and Dialers
  12. Please read Simple and easy ways to keep your computer safe and secure on the Internet.
  13. If you are using Internet Explorer, please consider using an alternate browser: Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built in popup blocker (as an added benefit!) that I have ever seen.
    Another good browser is Opera . Opera 9 comes loaded with the tools to keep you productive and safe. Try it today, it's absolutely free. Some of the Opera features are: Customization, BitTorrent, Content blocker, Add your favorite search engines, Thumbnail preview of tabs, Widgets, Transfer manager, Tabbed browsing, Password manager, Sessions (You can save a collection of open tabs as a session, for later retrieval, or start with the pages you had open when Opera was last closed.), Keyboard Shortcuts, Cookie control, a multitude of languages, Validate code, Toggle graphics and style sheets, and Special features such as Full-screen mode, Kiosk mode.
  14. Update all these programs regularly: Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
  15. If your computer was infected by a website, a program, IM, MSN, or p2p, check this site because it is Time To Fight Back.
Follow these steps and your potential for being infected again will reduce dramatically.
Good luck!

This subject is now closed. If you need this topic reopened, please contact a member of the HJT Team and we will reopen it for you. Include the address of this thread in your request. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.
You don't stop laughing when you get old; you get old when you stop laughing.
A Member of U-N-I-T-E (Unified Network of Instructors and Trained Eliminators)
Malware Removal University Masters Graduate

Posted Image
Join The Fight Against Malware
No reply within 5 days will result in your topic being closed. If you need more time, please let me know by posting in this topic so that your topic will not be closed.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users